Technology

macOS Under Attack: Ransomware EvilQuest comes with a keylogger

Ransomware that only targets MacOS systems is still relatively rare. EvilQuest is now a particularly nasty malware of this kind for Apple computers in circulation. It not only encrypts data but also brings a keylogger with it.

Nasty people keep coming back on Mac

OSX.EvilQuest: Security researcher Patrick Wardle is currently using this name to warn of a new malware that was developed for Apple systems. “It is not common for new ransomware that targets macOS to be discovered,” said Wardle in his first analysis – as ZDNet adds in its report, EvilQuest is only the third ransomware strain after KeRanger and Patcher that is exclusively on OSX -Computer has been tuned.

First of all, the pest has a classic ransomware effect. Once executed, data is encrypted and the user is informed of this with a text popup. However, this only really starts the problem for those affected: “After the encryption process has ended, the ransomware installs a keylogger to record all keystrokes of the user,” says security researchers.

Read This: LG Reportedly Attacked By Ransomware Developers

In addition, a reverse shell is set up in the system, which enables the attacker to connect to the infected host and execute user-defined commands. Finally, the malware looks for and steals typical files for cryptocurrency wallet applications. In short: With one application, the attackers achieve many goals here.

Infection risk low

If you then look at the analysis of possible routes of infection, a fairly well-known picture emerges: The pest was originally made public on June 29 by security researcher Dinesh Devadoss. Its investigations suggest that it has probably been distributed since the beginning of June. The gateway used: “EvilQuest is hiding in pirated macOS software that has been uploaded to torrent portals and online forums.”

Devadoss names a software package called “Google Software Update”, other security researchers have discovered EvilQuest in pirated copies of the DJ software “Mixed In Key” and the macOS security tool Little Snitch. According to the researchers, one can assume that many other applications from such sources are currently carrying the pest. The software also relies on users paying less attention to an installation warning. “macOS users who attempt to pirate software may ignore this warning,” said Wardle.

Recent Posts

What Is a Virtual Data Room? A Beginner’s Guide for First-Time Users

If you've never used one before, the term data room can sound more intimidating than…

18 hours ago

Apple Vision Pro: Company cuts hundreds of jobs in the VR and Siri team

High price, too much weight and a narrow niche: the Vision Pro headset forces Apple…

21 hours ago

US power grids: Trump declares a state of emergency

US President Donald Trump has ordered a new emergency regulation for the power grid. It…

21 hours ago

Huawei Opens Sales of Watch GT 7 Pro ahead of global launch

Huawei has officially launched the sale of the Watch GT 7 Pro in China, introducing…

21 hours ago

Apple to transform the next generation of smart glasses into a health and fitness product

Apple is considering the potential to transform its future smart glasses into health and fitness…

21 hours ago

6 Practical Ways to Stop Letting Your Past Define Who You Are

Everyone has parts of their past they'd handle differently if given another chance. Maybe you…

22 hours ago